The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-85094 represents a critical session hijacking vulnerability in the Canva Android application prior to version 2.376.0. The flaw stems from insufficient header validation in a privileged WebView context, allowing external origins to access sensitive HTTP response headers that should have been restricted. This vulnerability matters because WebViews in Android applications often run with elevated privileges and access to sensitive user data, including authentication tokens and session identifiers. Users of Canva on Android devices are affected, as an attacker who gains control of the WebView context—through malicious JavaScript injection, compromised website content, or man-in-the-middle attacks—can extract session credentials and impersonate the victim. With a CVSS score of 8.8, this represents a high-severity threat to user account security and data confidentiality.
While this CVE is not yet mapped to specific MITRE ATT&CK techniques, Casky.ai's platform would detect attack patterns associated with CWE-212 (Improper Cross-boundary Neutralization) through skills focused on client-side security control bypass and credential access. Practitioners using Casky would identify findings related to techniques like T1539 (Steal Web Session Cookie) or T1187 (Forced Authentication), as the vulnerability enables attackers to extract authentication headers and session tokens from the privileged WebView. The extended reasoning capabilities in Claude would help security teams understand the attack chain: initial WebView compromise → header enumeration → session token extraction → account takeover. Detection would flag anomalous header access patterns, privilege escalation within WebView contexts, and lateral movement attempts using stolen sessions, providing practitioners with actionable intelligence to prioritize patching and implement additional WebView security controls.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-85094. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation